Ethical Hacking

Learn to find vulnerabilities before the bad guys do! Gain real world hands on hacking experience in our state of the art hacking lab. Course designed and taught by expert instructors with years of penetration testing experience. 12 student maximum in every class. Certification attempt included in every package.
Computer Forensics Training at InfoSec Institute

Gain the in-demand skills of a certified computer examiner, learn to recover trace data left behind by fraud, theft, and cybercrime perpetrators. Discover the source of computer crime and abuse at your organization so that it never happens again. All of our class sizes are guaranteed to be 12 students or less to facilitate one-on-one interaction with one of our expert instructors.




Network Security US-CERT-Alerts
[Top] [All Lists]

US-CERT Cyber Security Alert SA06-275A -- Multiple Vulnerabilities in Ap

Subject: US-CERT Cyber Security Alert SA06-275A -- Multiple Vulnerabilities in Apple and Adobe Products
Date: Mon, 2 Oct 2006 14:14:05 -0400


-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA1

                        National Cyber Alert System

                      Cyber Security Alert SA06-275A


Multiple Vulnerabilities in Apple and Adobe Products

   Original release date: October 2, 2006
   Last revised: --
   Source: US-CERT


Systems Affected

     * Apple Mac OS X version 10.3.9 (Panther) and version 10.4.7 (Tiger)
     * Safari web browser
     * Adobe Flash Player

   These vulnerabilities affect both Intel-based and PowerPC-based Apple
   systems.


Overview

     Mac OS X, Safari, Adobe Flash Player, and other products are
     affected by multiple vulnerabilities. Apple has released Security
     Update 2006-006 to address these vulnerabilities, the most serious
     of which may allow a remote attacker to place and run malicious
     code on your computer.


Solution

Install an Update

     Install Apple Security Update 2006-006 through Apple Update.


Description

     Mac OS X, Safari, Adobe Flash Player, and other products are
     affected by multiple vulnerabilities. Some of these vulnerabilities
     could allow an attacker to run malicious programs on your computer.

     For more technical information, see US-CERT Technical Alert
     TA06-275A.


References

     * US-CERT Technical Cyber Security Alert TA06-275A -
       <http://www.us-cert.gov/cas/techalerts/TA06-275A.html>

     * About the security content of the Mac OS X 10.4.8 Update and
       Security Update 2006-006 -
       <http://docs.info.apple.com/article.html?artnum=304460>

     * Vulnerability Notes for Apple Security Update 2006-006 -
       <http://www.kb.cert.org/vuls/byid?searchview&query=apple-2006-006>

     * Mac OS X 10.4.8 Update (Intel) -
       <http://www.apple.com/support/downloads/macosx1048updateintel.html>

     * Mac OS X: Updating your software -
       <http://docs.info.apple.com/article.html?artnum=106704>

     * Vulnerability Notes for Adobe Security Bulletin APSB06-11 -
       <http://www.kb.cert.org/vuls/byid?searchview&query=apsb06-11>

     * Adobe Security Bulletin APSB06-11 -
       <http://www.adobe.com/support/security/bulletins/apsb06-11.html>

     * Securing Your Web Browser -
       <http://www.us-cert.gov/reading_room/securing_browser/#Safari>

 _________________________________________________________________

   The most recent version of this document can be found at:

     <http://www.us-cert.gov/cas/alerts/SA06-275A.html>
 _________________________________________________________________
 
 Feedback can be directed to US-CERT Technical Staff. Please send
 email to <cert@cert.org> with "SA06-275A Feedback VU#546772" in the
 subject.
 _________________________________________________________________

 Produced 2006 by US-CERT, a government organization.

 Terms of use:

   <http://www.us-cert.gov/legal.html>

 _________________________________________________________________

   Revision History

   October 02, 2006: Initial release
-----BEGIN PGP SIGNATURE-----
Version: GnuPG v1.2.1 (GNU/Linux)

iQEVAwUBRSFV0exOF3G+ig+rAQL2Lgf9HxBk3wOAAYr08EZxrkxat/8K/bUwMaPb
7vjvV6jkGr8SkdBnJ1MB24RCpYgh3+kGX2wXtUyAflReui3YH9yrteChQXPAEPBy
ZAD/VU/TAizp0ewbFk9QhWLIFJrADOhiTW0nlv4x8mwGZTn+QIJYhhyjiNI4cPzH
oxQID6FYi3pAdgtiM5/CHfauxdrceJ2VE6ZHRT/p8fAjsaN4AIiFwWnOWf84eo10
uZ5Um6+UctojZXaL2w7xolbcJrd3n1aLEXIaiLRz4nC9Ai2AOtgOKnHLJKh8A3zV
kN4tM6IGfXlc5YYcWIVlVjGrqrj/2DltjRPrg3Cow43y9keD2s99AA==
=v9IV
-----END PGP SIGNATURE-----

<Prev in Thread] Current Thread [Next in Thread>
  • US-CERT Cyber Security Alert SA06-275A -- Multiple Vulnerabilities in Apple and Adobe Products, US-CERT Alerts <=